GHSA-2823-qmq8-rwvj: vLLM: Loose `cache_salt` validation lets a single request kill EngineCore on LMCache-MP deployments — uncaught downstream `ValueError` denial of service
Summary
```json { "summary": "vLLM (an AI serving framework) accepts a `cache_salt` parameter from users but validates it too loosely—only checking that it's a non-empty string. When LMCache-MP (a caching connector) is enabled, this value gets passed to a stricter validator that rejects strings containing special characters like `/`, `@`, `\`, or null bytes, or longer than 128 characters. If an invalid string is sent, the resulting error crashes the entire engine process instead of just failing that o
Vulnerability Details
EPSS: 0.0%
Yes
October 5, 2026
Classification
Affected Vendors
Affected Packages
Related Issues
CVE-2026-47482: NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause missing release of memory
CVE-2022-29200: TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implem
Original source: https://github.com/advisories/GHSA-2823-qmq8-rwvj
First tracked: October 5, 2026 at 08:00 PM
Classified by LLM (prompt v3) · confidence: 95%